Skip to main content

API v2: key-pair authentication

Your integration authenticates with a key pair. The private key stays with you and signs every request; we store only the public key. There is no client_secret.

Nothing that leaks on our side lets anyone impersonate you, because there is nothing on our side to leak. A stolen access token is useless on its own: every call must be signed by a key we never hold.

What changes from v1​

v1v2
Credentialclient_id + client_secretclient_id + your public key
Token requestsecret in the bodyJWT signed by your private key
Token lifetime2 hours60 seconds
Stolen tokenworks until it expiresuseless without the private key
Per-request proofnoneDPoP proof, bound to method, URL, query and body
Revocationdisables the secretirreversible, and takes effect in about a second

v1 keeps working. v2 is a separate surface under /v2/*, so you migrate one integration at a time.

The addresses​

EnvironmentAuthenticationAPI
Sandboxhttps://api.sdb.lbpay.com.br/v2/oauth/tokenhttps://api.sdb.lbpay.com.br/v2/*
Productionhttps://api-secure.lbpay.com.br/v2/oauth/tokenhttps://api-secure.lbpay.com.br/v2/*

What a request looks like​

What you need to build​

Two short JWTs, both signed ES256 with your private key: the client assertion and the DPoP proof. Any library that signs a JWT does it, and so does your language's standard library. The examples in this section use no dependency for the signing part.